Critical Check Point SmartConsole Vulnerability Under Active Exploitation

Critical Check Point SmartConsole Vulnerability Under Active Exploitation

First seen 23 Jul 2026, 09:23 UTC ThehackernewsBleepingcomputerSecurityaffairs.CoFeeds.4SysopsFeeds2.Feedburner+11 89% similarity 79.5

Article Content

Browse articles
ThreatCluster

Check Point has confirmed a critical authentication bypass vulnerability, CVE-2026-16232, in its SmartConsole management tool, allowing unauthenticated attackers to gain full admin privileges. This vulnerability is actively being exploited in the wild, affecting a small number of customers with specific configurations that expose the Management Server to the internet without IP restrictions. The CVSS score for this vulnerability is 9.3, indicating its severity. Check Point has released patches and advised users to limit access to trusted IP addresses. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating a patch deadline of July 25, 2026. The vulnerability was first identified during a routine internal review, with evidence of exploitation dating back to April 2026. Organizations are urged to apply the available hotfixes immediately to mitigate risks.

Key Points: • CVE-2026-16232 allows unauthenticated access to Check Point SmartConsole with full admin rights. • The vulnerability has a CVSS score of 9.3 and is actively exploited in the wild. • CISA has mandated a patch deadline of July 25, 2026, for affected organizations.

ThreatCluster AI

Timeline

2024-05-28
CVE-2024-24919 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-08
CVE-2026-50751 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-22
CVE-2026-16232 published
Check Point disclosed a critical authentication bypass vulnerability affecting SmartConsole.
Rapid7
2026-07-22
CVE-2026-16232 added to CISA KEV
CISA included CVE-2026-16232 in its catalog of known exploited vulnerabilities, requiring urgent action.
Bleepingcomputer
2026-07-22
Patches released for CVE-2026-16232
Check Point released Jumbo Hotfixes to remediate CVE-2026-16232 and other vulnerabilities.
Rapid7
2026-07-22
CVE-2026-62145 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-22
CVE-2026-62144 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-23
Exploitation confirmed
Check Point confirmed that CVE-2026-16232 is being actively exploited, affecting a small number of customers.
Csoonline
2026-07-24
CISA mandates patching deadline
CISA set a July 25, 2026 deadline for federal agencies to patch CVE-2026-16232.
CISA

Community

Browse all →